You currently have javascript disabled. Several functions may not work. Please re-enable javascript to access full functionality.

Register a free account to unlock additional features at BleepingComputer.com

Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Memtuneup.exe And New.net

Hi new to this forum and I need help fast. Getting frustrated with these startup progys and Win Patrol keeps advising of hese new startups as well as Norton telling me a virus ndot net . How do I get rid of these files so they won't bug me again? Tried the Norton FixDnD exe utility but it keeps coming back...Anyone can you please help...Thanks

Thanks for getting back to me..I did the steps you suggested including procedure #4 from New.Net. I should say there was no directory of New.net nor could I find it in the HJT log. I ran Norton after cleaning and found no trace. I also ran the Norton "adware.NDot removal tool and came up clean. Can I assume it's gone?? BTW here is the new log:

First I noticed that you both norton antivirus and antivir personal edition. You really only want to have one antivirus software with real time protection running at the same time. If you have more than one this can slow down your compute. I personally do not like norton and would suggest the free version of avast or AVG any day. You can google for either of those programs. If you choose to use one of the two antivirus software that I just recommended, please uninstall the antivir and norton antivirus software.Next,

You have one (or more) of these programs running on your machine and that is good.

WinpatrolSpywareguardSpybot s&d (Teatimer option)

But prior to doing the fix below with hijackthis they need to be turned off.Please do the following.

Right click the running icon of spybot's teatimer, and choose exit.Right click the running icon of winpatrol, and choose exit.Right click the running icon of Spywareguard, it will open the program, Menu, file, exit, and confirm the programs close.

Unless they are turned off they could interfer with the fix by hijackthis.

Print out these instructions and then close all windows including Internet Explorer.

Then I want you to fix some of those entries. Please do the following:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

Thanks for getting back to me. I followed your instructions as follows:-uninstalled ANTIVIR and kept Norton-I showed hidden files-exited spybot's resident shield-exited winpatrol-I don"t have "Spywareguard" installed on my system (did you mean Spyware Blaster?)-I ram HJT scan and checked R0, 02,016DPF,016DPF'016 DPF' 018 Protocol-Rebooted computer and (BTW did not see any particular speed improvement)Ran a new HJT scan and here is the log. Please note the files seem above are still there from what I can see and also note the other file that was bugging me "memtuneup.exe" is there..Can I delete this file it still comes up often and denied by Teatimer...Thanks for you support....FrankLogfile of HijackThis v1.99.1Scan saved at 7:33:38 PM, on 12/19/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Hi Grinler,
Followed your instructions and the file MTLFS01.cab (containing the memclean.exe) file was sent. I'm wondering where I'm at with the New.Net file as it still gets detected by Teatimer. Did you notice any change in the latest HJT log?...Thanks again...Frank

You have one (or more) of these programs running on your machine and that is good.

WinpatrolSpywareguardSpybot s&d (Teatimer option)

But prior to doing the fix below with hijackthis they need to be turned off.Please do the following.

Right click the running icon of spybot's teatimer, and choose exit.Right click the running icon of winpatrol, and choose exit.Right click the running icon of Spywareguard, it will open the program, Menu, file, exit, and confirm the programs close.

Unless they are turned off they could interfer with the fix by hijackthis.

Next,

Print out these instructions and then close all windows including Internet Explorer.

Then I want you to fix some of those entries. Please do the following:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

Hi Grinler, I followed your instructions but note that none of the files you mention to "Fix" do not exist in the HJT log (see attached) except for the 018 Protocal: Festoon, which I fixed but always comes back. I think we were at the point of post #8. I sent you the MTLFS01.cab file and was waiting further instructions.Thanks

Download and Save blacklite to your desktop.F-Secure Blacklight: https://europe.f-secure.com/exclude/blacklight/index.shtmlDouble-click blbeta.exe then accept the agreement.leave [X]scan through windows explorer checked,click > scan then > next,You'll see a list of all items found.Don't choose for rename yet! I want to see the log first, because legit items can also be present there... like "wbemtest.exe"There must be also a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).Copy and paste this log along with the rootkit revealer log.

OK file Festoon is still there after the fix. It's not a suspect file, it's a little program to go along with Skype..Here is the log anyways..ThanksLogfile of HijackThis v1.99.1Scan saved at 12:27:24 PM, on 12/24/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

You sure its a legit file? Cant find much info on it and strange that it is not showing any associated info.

As for new.net I just dont see anything. Where is norton antivirus seeing it coming from? The problems with these antistartup programs is that they tend to block the symptoms from entering the registry so that we can even see them with hijackthis.